AI Software Support

Copilot readiness assessment and governed AI

Our customers do not want an AI project. They want AI that works, and does not open a door they cannot close.

Cyber Essentials Certified ISO 27001 Aligned Microsoft Cloud Solutions Provider 24/7 Monitoring Ofcom Registered ICO Registered

AI is the first technology in years that staff will adopt whether or not you have decided to. The risk is rarely the tool itself — it is that Copilot can instantly surface a decade of files nobody has looked at, including the ones with permissions that were never quite right. We are a security-first managed services provider, so we do this in that order: assess what your data would expose, close what it finds, then deploy under proper control. Afterwards, governance is part of your managed service rather than a project that ended.

POLICY GATESharePoint sitesFinance driveTicket historyHR recordsPolicy libraryAGENT

Assess first

AI enabled only after the data is governed

Least privilege enforced2 sources denied
Assessed
before Copilot
Logged
every query
Human
approval on actions

What is included

  • SharePoint data exposure review
  • Knowledge structure review
  • AI governance review
  • Deployment readiness summary
  • Recommended improvement plan
  • Delivered in days, not months

What changes

You find out before your staff do

A data exposure assessment before AI is enabled, not after someone surfaces the wrong document.

Every question is logged

A full audit trail of what was asked, what was accessed and what was done with it.

Actions need a person

Anything that changes a record or sends a message is presented for approval. AI proposes; people decide.

Method

How Keystone works

Assess

We review your data exposure first – SharePoint permissions, sharing links, structure. AI never meets your data before you know what it would find.

Secure

Close what the assessment found. Permissions tightened, legacy links retired, governance controls in place.

Connect

Your systems are connected one at a time, each deliberately scoped. CRM, service desk, finance – nothing by default.

Ask

Your team asks questions in Microsoft Teams and gets real answers from live systems. No new application, no training programme.

Govern

Every query logged, actions gated behind human approval, access reviewed as part of your managed service.

What the assessment looks at

Permissions that were never quite right

Copilot surfaces what a person already has access to. The problem is that access in most Microsoft 365 tenants has accumulated for years — inherited permissions, sharing links set to anyone, sites nobody owns. None of it mattered while finding a file required knowing where it was.

Whether your content can produce a good answer

AI reflects the structure it is given. Where the same document exists in four versions across three sites, the answers are confidently wrong, which is worse than no answer at all.

What is governing it

Tenant configuration, admin policy and audit settings decide what AI can reach and what is recorded when it does. This is the part that a client questionnaire or an auditor will eventually ask about.

Then a plan, in days

The output is a written summary of what was found, ranked by risk, with what to fix before enabling anything. If your data is already in reasonable shape it says so. Keystone is the next step once it is.

What it costs

Managed IT and security is priced per user, per month, with Microsoft/Google platform management charged as one flat monthly band on top. The full numbers are published rather than hidden behind a quote.

Next step

Before you turn Copilot on

Find out what it would surface. Thirty minutes, and you'll know whether your data is ready or whether it needs work first.

Book a Copilot readiness chat →